Re: Security Software Hack vs. Fedora

2020-12-17 Thread Todd Zullinger
Roberto Ragusa wrote: > and then the best: > - installs with: "curl http://random_site/install_script | sudo bash" Owww, my eyes! Please, make it stop. Any software I see which recommends that idiom in their instructions is immediately on the "never install this crapware under any circumstances.

Re: Security Software Hack vs. Fedora

2020-12-17 Thread Roberto Ragusa
On 12/17/20 6:58 PM, Jorge Fábregas wrote: Yes... and how the malicious bits were delivered thru the update mechanism...a nice reminder for us on how careful we need to be when adding 3rd-party repos be it yum repos, flatpak repos, container repos and so on. True. Even a single gpgcheck=0 is a

Re: Security Software Hack vs. Fedora

2020-12-17 Thread Garry T. Williams
On Thursday, December 17, 2020 10:08:54 AM EST Jonathan Ryshpan wrote: > I read that there has been a major security hack of at least two > companies, FireEye and SolarWinds, which supply security software > to the US Government and to major corporations. (see: > https://www.nytimes.com/2020/12/1

Re: Security Software Hack vs. Fedora

2020-12-17 Thread Jorge Fábregas
On 12/17/20 1:41 PM, stan via users wrote: > The deeper issue is that this illustrates how easy it is for skilled > programmers to insert malicious code into software so that it does > nefarious things while not being detected. That certainly affects > Fedora because it affects any system using co

Re: Security Software Hack vs. Fedora

2020-12-17 Thread stan via users
On Thu, 17 Dec 2020 07:08:54 -0800 Jonathan Ryshpan wrote: > I read that there has been a major security hack of at least two > companies, FireEye and SolarWinds,  which supply security software to > the US Government and to major corporations. >  (see: > https://www.nytimes.com/2020/12/16/opinio

Re: Security Software Hack vs. Fedora

2020-12-17 Thread Matthew Miller
On Thu, Dec 17, 2020 at 07:08:54AM -0800, Jonathan Ryshpan wrote: > I read that there has been a major security hack of at least two > companies, FireEye and SolarWinds,  which supply security software to > the US Government and to major corporations. >  (see:  > https://www.nytimes.com/2020/12/16/

Security Software Hack vs. Fedora

2020-12-17 Thread Jonathan Ryshpan
I read that there has been a major security hack of at least two companies, FireEye and SolarWinds,  which supply security software to the US Government and to major corporations.  (see:  https://www.nytimes.com/2020/12/16/opinion/fireeye-solarwinds-russia-hack.html  ).  Does this have any effect o